-
公开(公告)号:US20190394640A1
公开(公告)日:2019-12-26
申请号:US16287308
申请日:2019-02-27
Applicant: QUALCOMM Incorporated
Inventor: Soo Bum Lee , Anand Palanigounder , Adrian Edward Escott , Gavin Bernard Horn
Abstract: Systems and techniques are disclosed to protect a user equipment's international mobile subscriber identity by providing a privacy mobile subscriber identity instead. In an attach attempt to a serving network, the UE provides the PMSI instead of IMSI, protecting the IMSI from exposure. The PMSI is determined between a home network server and the UE so that intermediate node elements in the serving network do not have knowledge of the relationship between the PMSI and the IMSI. Upon receipt of the PMSI in the attach request, the server generates a next PMSI to be used in a subsequent attach request and sends the next PMSI to the UE for confirmation. The UE confirms the next PMSI to synchronize between the UE and server and sends an acknowledgment token to the server. The UE and the server then each update local copies of the current and next PMSI values.
-
公开(公告)号:US10362011B2
公开(公告)日:2019-07-23
申请号:US15160326
申请日:2016-05-20
Applicant: QUALCOMM Incorporated
Inventor: Soo Bum Lee , Gavin Bernard Horn , Anand Palanigounder
Abstract: In an aspect, a network supporting client devices includes one or more network nodes implementing network functions. Such network functions enable a client device to apply a security context to communications with the network when the client device is not in a connected mode. The client device obtains a user plane key shared with a user plane network function implemented at a first network node and/or a control plane key shared with a control plane network function implemented at a second network node. The client device protects a data packet with the user plane key or a control packet with the control plane key. The data packet includes first destination information indicating the first network node and the control packet includes second destination information indicating the second network node. The client device transmits the data packet or control packet.
-
公开(公告)号:US10334435B2
公开(公告)日:2019-06-25
申请号:US15286002
申请日:2016-10-05
Applicant: QUALCOMM Incorporated
Inventor: Soo Bum Lee , Anand Palanigounder , Adrian Edward Escott
IPC: H04L29/06 , H04W12/06 , H04L9/08 , H04W12/04 , H04W12/10 , H04W48/02 , H04W60/00 , H04W76/10 , H04W8/24 , H04W12/02
Abstract: A user equipment (UE) may be configured to transmit a registration message to a network to establish a secure connection for non-access stratum (NAS) messages between the network and a UE, the secure connection based at least in part on a UE identifier and security capabilities of the UE included in the registration message. The UE may then exchange NAS methods with the network over the secure connection. The UE may also establish, in response to the registration message, an authentication protocol with the network and encrypt subsequent NAS messages based in part on the authentication protocol.
-
公开(公告)号:US10299092B2
公开(公告)日:2019-05-21
申请号:US15337071
申请日:2016-10-28
Applicant: QUALCOMM Incorporated
Inventor: George Cherian , Jun Wang , Anand Palanigounder , John Wallace Nasielski
IPC: H04W76/00 , H04W4/00 , H04W4/70 , H04L12/701 , H04W76/11
Abstract: Systems and methods for control and triggering of machine to machine (M2M) devices (e.g., smart meters). More specifically how to allow an M2M service provider (e.g., utility company) to use an operator's network to communicate with the M2M device connected with a UE/GW associated with the operator's network. The M2M service provider may receive identification of the UE/GW, but not for the M2M device. By transmitting an identifier for the M2M device along with an identifier for the UE/GW, the network operator may define establish and maintain a communication path specific to M2M devices. Similar techniques may be incorporated to allow the M2M service provider to locate and trigger the M2M device.
-
公开(公告)号:US10178549B2
公开(公告)日:2019-01-08
申请号:US15708174
申请日:2017-09-19
Applicant: QUALCOMM Incorporated
Inventor: Anand Palanigounder
Abstract: Systems and methods for providing authentication key agreement (AKA) with perfect forward secrecy (PFS) are disclosed. In one embodiment, a network according to the disclosure may receive an attach request from a UE, provide an authentication request including a network support indicator to a network resource, receive an authentication token from the network resource, such that the authentication token includes an indication that a network supports PFS, provide the authentication token to the UE, receive an authentication response including a UE public key value, obtain a network public key value and a network private key value, determine a shared key value based on the network private key value and the UE public key value, bind the shared key value with a session key value to create a bound shared key value, and use the bound shared key value to protect subsequent network traffic.
-
公开(公告)号:US10097995B2
公开(公告)日:2018-10-09
申请号:US15160245
申请日:2016-05-20
Applicant: QUALCOMM Incorporated
Inventor: Soo Bum Lee , Gavin Bernard Horn , Anand Palanigounder , Stefano Faccin
IPC: H04W12/06 , H04W68/00 , H04W40/02 , H04L29/06 , H04W12/04 , H04W76/38 , H04W76/34 , H04W4/70 , H04W12/02
Abstract: In an aspect, a network supporting a number of client devices may include a network device that establishes a security context and generates a client device context. The client device context includes network state information that enables the network to communicate with the client device. The network device generates one or more encrypted network reachability contexts based on the client device context, and transmits the one or more encrypted network reachability contexts to a network entity. The one or more encrypted network reachability contexts enable the network device to reconstruct the context for the client device when the network device receives a message to be transmitted to the client device from the network entity. As a result, the network device can reduce an amount of the context for the client device maintained at the network device in order to support a greater number of client devices.
-
公开(公告)号:US09883384B2
公开(公告)日:2018-01-30
申请号:US14596953
申请日:2015-01-14
Applicant: QUALCOMM Incorporated
Inventor: Soo Bum Lee , Gavin Bernard Horn , Anand Palanigounder
IPC: H04W12/04 , H04W12/06 , H04W4/00 , H04W8/04 , H04W48/02 , H04W60/00 , H04W76/02 , H04W12/08 , H04W8/18 , H04L29/06 , H04W8/20
CPC classification number: H04W12/04 , H04L63/0853 , H04L63/18 , H04W4/005 , H04W4/70 , H04W8/04 , H04W8/18 , H04W8/205 , H04W12/06 , H04W12/08 , H04W48/02 , H04W60/00 , H04W76/023 , H04W76/14
Abstract: Methods, systems, and devices for wireless communication are described. A user equipment (UE) may obtain identification information for a device and may assist in establishing credentials by which the device accesses a wireless network. The UE may establish a connection with the wireless network using its own credentials, and register the device to access the wireless network by associating the identification information for the device with the credentials of the UE. The UE may receive or establish credentials by which the device accesses the wireless network and may communicate these credentials to the device over a local connection. In some cases, the UE may authenticate the device's identification information to determine whether the device is allowed to be registered with the wireless network.
-
公开(公告)号:US09825937B2
公开(公告)日:2017-11-21
申请号:US14794452
申请日:2015-07-08
Applicant: QUALCOMM Incorporated
Inventor: Kalle Ilmari Ahmavaara , Anand Palanigounder
CPC classification number: H04L63/0823 , G06F21/62 , H04L63/166 , H04L63/205 , H04W12/04 , H04W12/06
Abstract: A method for authentication, operational in a device configured to communicate with a Long-Term Evolution (LTE) network, is described. The method includes receiving a first message from the LTE network that indicates the LTE network supports establishment of an LTE security context based on executing certificate-based authentication in lieu of subscriber identity module (SIM)-based authentication. The method also includes communicating one or more messages with the LTE network to execute certificate-based authentication. The method further includes establishing the LTE security context based on keys derived from the certificate-based authentication.
-
公开(公告)号:US09801055B2
公开(公告)日:2017-10-24
申请号:US14825988
申请日:2015-08-13
Applicant: QUALCOMM Incorporated
Inventor: Anand Palanigounder
CPC classification number: H04W12/04 , H04L9/0841 , H04L9/085 , H04L9/0891 , H04L9/3066 , H04L9/3242 , H04L63/0428 , H04L63/067 , H04L63/0869 , H04W12/06
Abstract: Systems and methods for providing authentication key agreement (AKA) with perfect forward secrecy (PFS) are disclosed. In one embodiment, a network according to the disclosure may receive an attach request from a UE, provide an authentication request including a network support indicator to a network resource, receive an authentication token from the network resource, such that the authentication token includes an indication that a network supports PFS, provide the authentication token to the UE, receive an authentication response including a UE public key value, obtain a network public key value and a network private key value, determine a shared key value based on the network private key value and the UE public key value, bind the shared key value with a session key value to create a bound shared key value, and use the bound shared key value to protect subsequent network traffic.
-
公开(公告)号:US09787478B2
公开(公告)日:2017-10-10
申请号:US14736055
申请日:2015-06-10
Applicant: QUALCOMM Incorporated
Inventor: Jangwon Lee , Anand Palanigounder , Soo Bum Lee , Rajat Prakash
CPC classification number: H04L9/3268 , H04L9/0894 , H04L9/321 , H04L9/3247 , H04L9/3263
Abstract: A method includes: establishing a telecommunication link between a device and a service provider system via a telecommunication network; receiving a device public key via the telecommunication network from the device at the service provider system, the device public key predating the establishment of the telecommunication link; verifying, at the service provider system, that the device stores a device private key in a secure storage area of the device, the device private key corresponding to the device public key, the device public key and the device private key being a cryptographic key pair; and authorizing, by the service provider system, sign-up of the device for service enrollment in response to verifying that the device stores the device private key in the secure storage area of the device.
-
-
-
-
-
-
-
-
-